{"schema_version":"1.7.3","id":"SUSE-SU-2021:1458-1","published":"2021-04-30T10:58:51Z","modified":"2026-02-04T02:16:12.876879Z","related":["CVE-2018-16873","CVE-2018-16874","CVE-2018-16875","CVE-2019-16884","CVE-2019-19921","CVE-2019-5736","CVE-2021-21284","CVE-2021-21285","CVE-2021-21334"],"upstream":["CVE-2018-16873","CVE-2018-16874","CVE-2018-16875","CVE-2019-16884","CVE-2019-19921","CVE-2019-5736","CVE-2021-21284","CVE-2021-21285","CVE-2021-21334"],"summary":"Security update for containerd, docker, runc","details":"This update for containerd, docker, runc fixes the following issues:\n\n- Docker was updated to 20.10.6-ce\n  *  Switch version to use -ce suffix rather than _ce to avoid confusing other\n     tools (bsc#1182476).\n  * CVE-2021-21284: Fixed a potential privilege escalation when the root user in \n    the remapped namespace has access to the host filesystem (bsc#1181732)\n  * CVE-2021-21285: Fixed an issue where pulling a malformed Docker image manifest \n    crashes the dockerd daemon (bsc#1181730). \n\n- runc was updated to  v1.0.0~rc93 (bsc#1182451 and bsc#1184962).\n  * Use the upstream runc package (bsc#1181641, bsc#1181677, bsc#1175821).\n  * Fixed /dev/null is not available (bsc#1168481).\n  * Fixed an issue where podman hangs when spawned by salt-minion process (bsc#1149954).\n  * CVE-2019-19921: Fixed a race condition with shared mounts (bsc#1160452).\n  * CVE-2019-16884: Fixed an LSM bypass via malicious Docker image that mount \n    over a /proc directory (bsc#1152308).\n  * CVE-2019-5736: Fixed potential write attacks to the host runc binary (bsc#1121967).\n  * Fixed an issue where after a kernel-update docker doesn't run (bsc#1131314 bsc#1131553)\n  * Ensure that we always include the version information in runc (bsc#1053532).\n  \n- Switch to Go 1.13 for build.\n  * CVE-2018-16873: Fixed a potential remote code execution (bsc#1118897).\n  * CVE-2018-16874: Fixed a directory traversal in 'go get' via curly braces \n    in import paths (bsc#1118898).\n  * CVE-2018-16875: Fixed a CPU denial of service (bsc#1118899).\n  * Fixed an issue with building containers (bsc#1095817).\n\n- containerd was updated to v1.4.4\n  * CVE-2021-21334: Fixed a potential information leak through environment variables (bsc#1183397).\n  * Handle a requirement from docker (bsc#1181594).\n  * Install the containerd-shim* binaries and stop creating (bsc#1183024).\n  * update version to the one required by docker (bsc#1034053)\n\n- Use -buildmode=pie for tests and binary build (bsc#1048046, bsc#1051429)\n- Cleanup seccomp builds similar (bsc#1028638).\n- Update to handle the docker-runc removal, and drop the -kubic flavour (bsc#1181677, bsc#1181749)\n","affected":[{"package":{"name":"containerd","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.4-16.38.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.4.4-16.38.1","docker":"20.10.6_ce-98.66.1","runc":"1.0.0~rc93-16.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:1458-1.json"}},{"package":{"name":"docker","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.10.6_ce-98.66.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.4.4-16.38.1","docker":"20.10.6_ce-98.66.1","runc":"1.0.0~rc93-16.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:1458-1.json"}},{"package":{"name":"runc","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0~rc93-16.8.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.4.4-16.38.1","docker":"20.10.6_ce-98.66.1","runc":"1.0.0~rc93-16.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:1458-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20211458-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1028638"},{"type":"REPORT","url":"https://bugzilla.suse.com/1034053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1048046"},{"type":"REPORT","url":"https://bugzilla.suse.com/1051429"},{"type":"REPORT","url":"https://bugzilla.suse.com/1053532"},{"type":"REPORT","url":"https://bugzilla.suse.com/1095817"},{"type":"REPORT","url":"https://bugzilla.suse.com/1118897"},{"type":"REPORT","url":"https://bugzilla.suse.com/1118898"},{"type":"REPORT","url":"https://bugzilla.suse.com/1118899"},{"type":"REPORT","url":"https://bugzilla.suse.com/1121967"},{"type":"REPORT","url":"https://bugzilla.suse.com/1131314"},{"type":"REPORT","url":"https://bugzilla.suse.com/1131553"},{"type":"REPORT","url":"https://bugzilla.suse.com/1149954"},{"type":"REPORT","url":"https://bugzilla.suse.com/1152308"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160452"},{"type":"REPORT","url":"https://bugzilla.suse.com/1168481"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175081"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175821"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181594"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181641"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181677"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181730"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181732"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181749"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182451"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182476"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182947"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183024"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183397"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184768"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16875"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-19921"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5736"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21284"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21285"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21334"}]}